Cybersecurity Course
Check out our modules, batch schedules, syllabus brochures and certification options.
View course detailsTable of Contents
What cyber security is
Learn in order: IT and networking fundamentals, operating systems and Linux, security principles and common threats, then practise in hands-on labs, choose a defensive or offensive direction, and layer on certifications like Security+, CEH or OSCP. Build fundamentals before tools — they outlast any single technology.
Cyber security is the practice of protecting systems, networks and data from digital attacks. It’s a broad field — from defensive monitoring to authorized offensive testing to compliance — which can feel overwhelming at the start. The good news is that there’s a sensible order to learn it in, and following that order is what turns an intimidating subject into a manageable, step-by-step path. This roadmap lays out that path — with honest timelines — so you always know what to learn next, and why.
The roadmap at a glance
Six stages take you from complete beginner toward job-ready. They overlap somewhat (you keep practising in labs throughout), but the order matters: each stage makes the next one make sense.
| # | Stage | Focus | Rough time |
|---|---|---|---|
| 1 | IT, networking & OS fundamentals | How systems & networks work — IP, ports, TCP/IP, DNS, protocols; Windows & Linux basics | ~2–3 months |
| 2 | Linux & the command line | Linux file system, permissions, packages & terminal fluency | ~1–2 months |
| 3 | Security principles & threats | CIA triad, attack types, defence, cryptography basics, frameworks | ~1–2 months |
| 4 | Hands-on labs (home lab) | Safe, legal practice — VMs, vulnerable machines, TryHackMe/HTB, CTFs | Ongoing |
| 5 | Choose a path | Defensive (SOC) vs offensive (pen-test); also cloud, GRC | Decide by ~month 6 |
| 6 | Certifications | Security+ → CEH → (later) OSCP — plus a portfolio | Layered on |
The golden rule, repeated by almost everyone who’s done it: don’t skip the fundamentals to rush into tools. Tools are easy to learn once you understand the networking and security concepts underneath; without that, you’re memorising commands you can’t reason about.
Stage 1: IT, networking & OS fundamentals
Everything starts here, because you can’t secure what you don’t understand. Learn how computers and networks actually work: IP addressing, ports, TCP/IP, DNS, routing, packets and common protocols (HTTP/HTTPS, SSH), plus operating-system basics on both Windows and Linux — files, users, permissions. Aim for roughly CCNA-level networking knowledge; you don’t need to be a network engineer, but you do need to reason confidently about how traffic moves. Free resources cover this well. This is the foundation that makes firewalls, encryption and intrusion detection understandable later — skip it and nothing else clicks. Expect a couple of months here.
Stage 2: Linux & the command line
So much of security runs on Linux that command-line comfort is essential. Get fluent with the Linux file system, permissions, package management and the terminal — ideally by installing a distribution (or Kali Linux in a virtual machine) and actually using it daily. Interactive, hands-on resources teach this far better than reading. You don’t need to be a system administrator, but you should be able to navigate, manage files and permissions, and run tools confidently from a terminal. A focused month or two builds real fluency.
Stage 3: security principles & threats
Now you shift from “user” to “defender”. Learn the core security concepts: the CIA triad (confidentiality, integrity, availability), common attack types and how defences counter them, the basics of cryptography, and the frameworks organisations actually use (such as NIST, ISO 27001, CIS and MITRE ATT&CK). A great structured way to cover all of this is to study a CompTIA Security+ curriculum — even if you sit the exam later, the syllabus gives you a comprehensive, industry-recognised grounding in every foundational concept. This stage is where security finally starts to feel like security.
Stage 4: hands-on labs (home lab)
Practise legally and safely. Build a home lab using virtual machines on your own computer — for example a Kali Linux VM plus intentionally vulnerable targets like DVWA or Metasploitable — and use purpose-built, authorized platforms (TryHackMe, Hack The Box, PortSwigger’s Web Security Academy, OverTheWire). Never test systems you don’t own or aren’t authorized to test.
Reading about security and doing security are very different things, and this is the stage that builds real skill. In your safe, isolated lab and on authorized platforms, apply what you’ve learned: practise the concepts, take on capture-the-flag (CTF) challenges, and document your work in write-ups. That hands-on practice — and the portfolio of write-ups it produces — is exactly what employers and practical certifications value, and it builds confidence far faster than theory. This isn’t a one-off stage; you keep practising throughout the rest of the roadmap.
| Practice (legal, authorized) | TryHackMe, Hack The Box, PortSwigger Web Security Academy, OverTheWire |
|---|---|
| Free learning | Professor Messer (Security+/Network+), Cybrary, NPTEL, OWASP, MITRE ATT&CK, NIST |
| Vulnerable lab targets | DVWA, Metasploitable & similar — run inside your own VMs only |
Stage 5: choose a path (defensive vs offensive)
Cyber security is too broad to master all at once, so after building your foundation — typically around the six-month mark — pick a direction and go deeper. The main choice is defensive vs offensive, though cloud security and GRC are strong options too.
| Path | What it involves | Honest note |
|---|---|---|
| Defensive (Blue team) | Monitoring, detection & response (SOC), incident response, forensics | Easiest entry; biggest hiring area; SOC Analyst L1 is the common first role |
| Offensive (Red team) | Authorized penetration testing & ethical hacking | Fewer junior roles; harder to break into; usually needs more hands-on proof |
| Cloud / GRC | Cloud security; or governance, risk & compliance | Growing; GRC is a faster non-tech-heavy entry; cloud pays well |
For most beginners, a defensive (SOC) role is the realistic first job, because that’s where the most entry-level openings are; offensive roles are fewer and harder to land at junior level. Choose based on what genuinely interests you — you’ll learn faster — and remember the fundamentals let you switch paths later.
Stage 6: certifications (Security+, CEH, OSCP)
Certifications validate your knowledge and help with hiring — but skills matter more than certificates, so layer them onto real ability rather than collecting them. The common, honest ladder:
| Certification | Where it fits | Issued by |
|---|---|---|
| CompTIA Security+ | Foundational, vendor-neutral — a strong first cert | CompTIA — cheapest entry |
| CEH | Ethical-hacking path; widely recognised in India | EC-Council — premium-priced |
| OSCP | Advanced, hands-on (later, after experience) | Offensive Security |
Start with CompTIA Security+ (foundational, affordable), add CEH if you’re heading toward ethical hacking, and treat OSCP as a later, advanced goal after you’ve built experience. Remember these are issued by their respective bodies (CompTIA, EC-Council, Offensive Security), not by any training institute — a course or self-study prepares you; you sit the exam with the body. One solid foundation cert plus a real portfolio beats a stack of certificates with no hands-on proof.
How long each stage takes (honest)
Honest estimates, not promises — your pace depends on your starting point and study time. Be sceptical of anyone claiming you can become job-ready in weeks. [verify – indicative, mid-2026]
| Phase | Rough time | What happens |
|---|---|---|
| Foundations (Stages 1–3) | ~3–5 months | Networking, Linux, OS & security principles |
| Hands-on + specialise (Stage 4–5) | ~3–4 months | Labs, CTFs, choose a path, deepen skills |
| Cert + portfolio + apply (Stage 6) | ~2–4 months | First cert, portfolio, start applying |
| Total (from scratch) | ~12–18 months | Less (6–12) with an IT/coding background |
The headline: from a standing start, realistically about 12–18 months of consistent effort to be job-ready for an entry role — roughly 6–12 months if you already have an IT, networking or coding background. Studying part-time around work or college stretches this, which is normal. Consistency and hands-on practice are what move you along; there is no genuine 30-day shortcut.
Do you need coding?
Not to begin, but it helps and matters more as you specialise. Basic scripting — especially Python, plus some Bash — lets you automate tasks (like scanning ports or parsing logs) and understand how exploits work. You don’t need to become a full-time programmer; aim to be comfortable reading and writing simple, useful scripts. Coding becomes more important on the offensive and tooling side, and less essential for many entry-level defensive (SOC) roles — so you can start the roadmap without it and build it as you go.
Common roadmap mistakes
A few honest pitfalls trip up most beginners. Avoiding them is most of the battle:
Jumping into hacking tools before fundamentals
Trying to learn everything at once instead of picking one path
Collecting certificates instead of building real skills
Only reading — not practising hands-on in labs
Waiting until you feel ‘fully ready’ to apply
Ignoring soft skills like report-writing & communication
The thread running through all of these: pick one path, build fundamentals before tools, practise hands-on rather than only reading, and don’t wait to feel “fully ready” before applying — most security teams expect to train junior hires. Communication matters too: being able to explain risk and write a clear report is often what turns a good candidate into a hired one.
Where a course fits
You can absolutely follow this roadmap with free resources and self-discipline, and many people do. A structured course mainly compresses and de-risks the early stages — giving you guided fundamentals, real hands-on labs, a clear route through specialisation, certification prep and accountability — which can be faster and less confusing than self-teaching. If that appeals, Course Unbox’s Cyber Security programme broadly follows this same path (foundations → labs → specialise → certify), taught live by a practitioner (Bhavyam Verma), online or in Noida, from ₹35,000 with EMI, with an internship. You can book a free demo — call/WhatsApp +91-8923660886 — to see how it maps to the roadmap. Whichever route you take, the order on this page stays the same.
Related resources

About the author
Jugal Chauhan
Founder, Course Unbox
Jugal Chauhan is the founder of Course Unbox and a digital marketing and SEO practitioner with 12+ years of experience. He has driven growth for brands like Bata India and Airtel and led teams at leading edtech companies, and now teaches SEO and digital marketing to thousands of learners through live, project based cohorts.